We have been using CSF on cPanel quite successfully for years and over the last couple of years, we have started using them on Virtualmin/Webmin servers as well. The difference we see is that while CSF is very well optimized for cPanel with lot of additional custom configuration like monitoring unwanted scripts, monitoring exim login attempts and blocking them if necessary, monitoring service...
my /usr/local/cpanel/logs/login_log is full of failed whm login attempts from ip addresses in verry strange countrys but it looks like the attackers know the defending mechanism against this type of attack because they stop after two failed attempts and a few hours hours later they try again.
I know this would be a working as designed status as my LF_CPANEL is set to 5 so it only...
Is the intended behavior that csf /lfd will only email upon the first WHM root access from the same IP within so many hours?
I'm trying to figure out why lfd only sent one email WHM/Cpanel root access alert when I logged in and out and then in again a few times to WHM. The cpanel login_log shows all three WHM logins, but lfd only emailed once and only logged the first whm login to...
In csf v14.09 when I have permanent deny rules in /etc/csf/csf.deny like the following:
tcp|in|d=1_65535|s=64.62.128.0/17 # do not delete
tcp|in|d=1_65535|s=64.71.32.0/19 # do not delete
tcp|in|d=1_65535|s=64.71.128.0/18 # do not delete
tcp|in|d=1_65535|s=64.90.32.0/19 # do not delete
tcp|in|d=1_65535|s=64.91.224.0/19 # do not delete
tcp|in|d=1_65535|s=64.225.0.0/17 # do not delete...
Hi
I have a recurring issue on my 2 cpanel/whm controlled vps servers CENTOS 7.9 kvm v94.0.3 .
I have installed csf and lfd as per 'the book' BUT, if I leave service csf enabled the load average gradually ramps up to a huge and non resposive value (I have seen 30 30 30!! - that took some recovery from)
However as soon as I 'systemctl stop csf' the load averages rapidly drop to their usual values...
whoops... silly error. I was placing my ignore commands under IP Blocking rather than process blocking ... completely missed the drop-down list of ignore options.
Hello!
Help me please to get rid of hundreds firewall messages in bash, like this:
New messages appears every few seconds, so in a minute screen is full of them. It's hard to type any command in bash.
Is it possible to redirect output of this messages to some log file instead?
Hi there. Lately I was getting a lot of errors like
*Error* pid mismatch or missing, at line 1160
daemon stopped
This error is caused by trying to block some IP address, which triggered csf of lfd rule few times in a row. After that csf is disabled, but it was reenabled by cron job, which monitors services state
This is from lfd.pl (including line 1160, where an error is triggered)
while (1)...
I get a huge amount of e-mail notifications such as the ones below on a daily basis:
Time: Sun Nov 15 12:45:01 2020 +0000
IP: 191.239.XXX.XX (BR/Brazil/-)
Failures: 3 (sshd)
Interval: 3600 seconds
Blocked: Permanent Block
Log entries:
Nov 15 12:30:49 server sshd : Invalid user git from 191.239.XXX.XX port 45826
Nov 15 12:30:51 server sshd : Failed password for invalid user git from...
I try to set restriction to user and not general SMTP restriction.
As I understand SMTP_BLOCK should be ON and additional per user
2. SMTP_ALLOWUSER XXXuser
Hi
i am working IPTV and i need the the firewall for my main server
but i have some question
1. CFS can block DDOS attacks?
2. Do I need a dedicated server for firewall? i don't want run it on main server
3. has CFS any monitoring panel for delete ip or add ip and check statues during attacks?
You cannot post new topics in this forum You cannot reply to topics in this forum You cannot edit your posts in this forum You cannot delete your posts in this forum